Conn_track values is for everybody, every host, every device, the world.
WAN MTU should be capped to 1500 at home. I’ve never heard of an ISP that can carry jumbo frames inter-AS for residential.
Largest possible MTU on LAN everywhere is fine, as long as L3 MTU matches on all routers, switches, whatever. The bridge will auto select smallest MTU like 2290 on MikroTik Wireless APs.
The RFC6890 route to black hole is applicable for every network device excluding hosts.
TCP MSS clamping is never required in a properly implemented set up i.e. proper MTU end to end. I never needed it for WireGuard or anything else.
No, you don’t need that bridge loop prevention in a home environment.