Credentials and attachments
Provider credentials stay with the local provider tools. Attachments should be treated as sensitive input.
Provider credentials
Horme checks whether Claude Code and Codex are available and signed in. It does not collect or store their credentials.
Attachments
An attachment can contain source code, customer data, or secrets. Accepted files are copied into the trusted project and compatible Claude Code or Codex runs receive the local path. Include only what the objective requires, because the selected provider may read that content.