~/.agent-os/config.json or in the environment; never commit them to the repo.~/.agent-os/configs/<skill_id>.json; keep that directory out of public repos.~/.agent-os/workspaces/{agent_id}/. File-access tools are restricted to this path (resolveInWorkspace); agents cannot read/write outside it.