Atomic turns notes into a searchable graph and generated reference
Atomic stores Markdown notes as atoms, then chunks and embeds them for semantic search. Similarity drives links and a spatial canvas, while language models can extract hierarchical tags, synthesize cited wiki articles, answer questions, and produce scheduled reports from the stored material. The source note remains the unit a user reads and edits, which is easier to audit than a knowledge product that hides everything inside a chat transcript.
The application reaches beyond the desktop. A Chromium extension captures pages, an iOS client reads and writes atoms, RSS feeds can create new entries, and multiple databases share one registry. The repository's primary GitHub language is Rust, with a React frontend and Tauri 2 desktop shell. That breadth makes Atomic a full application rather than a reusable note-processing library.
What happened when we ran it
Our sandbox installed 928 npm packages in 22 seconds and consumed 515 MB on disk. The build completed in another 22 seconds, and the supplied test command passed in 11 seconds. At commit 825e223, the checkout held 997 files, about 239,666 lines of source, and 19.8 MB before the installed dependency tree.
The audit result changes the recommendation. Npm reported 29 known vulnerabilities: 3 critical, 16 high, 8 moderate, and 2 low. Our measurement does not say which application paths are reachable or whether a compensating control exists, so it would be wrong to turn the count into 29 exploitable Atomic bugs. It does establish that the installed tree needs investigation before an internet-facing deployment.
Our scan also found 5 CI workflow files, a Dockerfile, and Compose configuration, with no directory literally named tests. The passing 11-second test command shows that test coverage exists somewhere in the project structure. These results cover repository mechanics in a fresh 3-CPU, 8 GB Debian container; they do not measure search quality, embedding accuracy, or generation quality.
Docker starts three services and still needs an AI provider
The Compose route starts the API server, web frontend, and nginx reverse proxy. An ATOMIC_SETUP_TOKEN lets the first browser claim the instance. The standalone Rust server and Fly.io instructions provide other deployment paths, while desktop releases bundle a Tauri client with the server sidecar. Persistent storage and backups remain the operator's job in a self-hosted setup.
Atomic cannot generate its semantic layer from SQLite alone. OpenRouter, Ollama, or another OpenAI-compatible endpoint supplies embeddings and language-model calls for tagging, wikis, reports, and chat. Ollama is the privacy-oriented choice when suitable models fit locally. A hosted API means notes or derived prompt material leave the machine under that provider's policy, even though the Atomic database stays under your control.
MCP grants both reading and writing access to the knowledge base
The embedded MCP server exposes semantic search, similar-note lookup, tag and database browsing, wiki and report retrieval, plus tools to create, ingest, update, and edit atoms. Desktop mode uses a bundled stdio-to-HTTP bridge that reads the local token. A remote client connects to /mcp with a bearer token created in settings or by the server CLI.
That is useful for Claude Code or another agent that needs durable project research, but the token is powerful. It can change the same knowledge base used for later retrieval. Give each remote client its own revocable token, keep the 515 MB application stack behind HTTPS, and avoid placing the endpoint on the public internet before reviewing the 3 critical and 16 high audit findings.
Generated wikis depend on source quality and provider behavior
Wiki synthesis includes inline citations back to atoms, which gives readers a path to inspect supporting notes. Release v1.45.0 fixed structured generation that could silently return empty tags or wiki updates with some providers. It also changed gateway-padded success responses into retryable failures and improved schema instructions for smaller local models. These fixes show why provider compatibility deserves its own acceptance set.
Staleness is another limit. Open issue 157 describes notes about fast-changing subjects remaining available to chat after their useful date because Atomic has no valid_until field, expired-note view, or filter. Citations prove where an answer came from, not that the source is current. Anyone storing operational or health research should add dated tags and review routines until the product can enforce expiry.
The capture system still has platform and media gaps
The browser extension queues captures offline and syncs them when the server returns. The README links the Chrome Web Store, while issue 208 asks for Firefox support. Users committed to Firefox or a Firefox-derived browser will need another import route. RSS ingestion and direct URL ingestion cover some of that gap, though they are not a replacement for clipping an authenticated page.
Atoms are Markdown-first. Issue 232 requests first-class uploaded images, audio, video, and general attachments, which means that media-library use is outside the documented feature set today. Atomic can store source URLs and captured web content, but buyers migrating a notebook full of scans, recordings, and PDFs should test the importer against a representative folder before choosing it as the permanent home.
August 2026 releases show active work on AI failure modes
GitHub recorded 1,927 stars and 31 combined open issues and pull requests when fetched. The last push was August 9, 2026, followed minutes later by v1.45.0. Issue activity continued through August 18. The release cadence and detailed failure fixes indicate active maintenance, while the issue list still contains product gaps around media, expiry, and browser support.
Atomic is a persuasive package for one person's research archive because notes, search, synthesis, capture, mobile access, and MCP all share the same data. Our 55-second successful run lowers the cost of evaluating it. The 29 dependency advisories raise the cost of deploying it carelessly, so the sensible trial is local, backed up, and kept away from an exposed server until the audit is understood.

