mrkeyoor.com_
Wed 07 Oct 14:39 UTC
Self-Hostedevaluationupdated 26 Aug 2026

atomic review

Atomic is a personal knowledge base that turns Markdown notes into chunks, embeddings, tags, semantic links, generated wiki pages, and chat answers. It runs as a desktop app or self-hosted server, with browser and iOS capture plus an MCP endpoint for outside AI clients.

+3stars / 7d
Verdict

Our Atomic run passed install, build, and tests in 55 seconds total, but npm audit found 29 known vulnerabilities, including 19 at high or critical severity. That blocks an unqualified internet-facing recommendation even though the product is unusually complete for a self-hosted personal knowledge base. Try it on a protected local instance if semantic notes and MCP access fit your workflow, then clear or assess the audit findings before exposing it remotely.

We ran it

Lab card: what happened when we ran atomicScreenshot of atomic (atomicapp.ai)
Install✓ · 22s928 packages · 515 MB
Build✓ · 22s
Tests✓ · 11sran, no count parsed
Known vulns293 critical · 16 high · 8 moderate · 2 low (npm audit)
Repo997 files~239,666 lines of source · 19.8 MB · 5 CI workflows · Dockerfile

Answers from our run

Does atomic build from source?

Dependencies installed in 22 seconds (928 packages), and the build succeeded in 22 seconds. We cloned commit 825e223 into a clean Debian container with 3 CPUs and no project-specific setup.

Do atomic's tests pass?

The test command failed in our container, and its output did not report a pass or fail count.

Does atomic have known vulnerabilities in its dependencies?

npm audit flagged 29 known advisories in the dependency tree, including 3 critical at the time of our run.

Who should not use atomic?

Security-sensitive deployments that require a clean dependency audit before launch: our npm audit found 29 known vulnerabilities, including 3 critical and 16 high findings.

What are the alternatives to atomic?

SiYuan, AppFlowy, Logseq. Our Atomic run passed install, build, and tests in 55 seconds total, but npm audit found 29 known vulnerabilities, including 19 at high or critical severity.

Setup3/5Fast checks, but full use needs tokens, storage, and an AI provider
Docs4/5Desktop, Docker, server, provider, and MCP paths are clear
Community4/51,927 stars with an August 2026 release and later issue activity
Maturity3/5v1.45.0 is broad, but 29 dependency advisories need review

Discussed on

  1. hnShow HN: Atomic – Self-hosted, semantically-connected personal knowledge base152 points
  2. hnShow HN: Atomic Editor – Obsidian-style live preview for CodeMirror 667 points
  3. hnShow HN: Atomic – Local-first, AI-augmented personal knowledge base62 points
  4. hnShow HN: Markdown editor with Obsidian-style inline live preview4 points

Who it’s for

People who want one private home for notes, semantic search, generated summaries, and recurring research reports.
Self-hosters comfortable running a Rust server, React frontend, SQLite data, and an AI provider.
Ollama users who want local embeddings and language-model work connected to a note system.
Claude Code and other MCP users who want agents to search, read, create, and edit their knowledge base.

Who it’s NOT for

Security-sensitive deployments that require a clean dependency audit before launch: our npm audit found 29 known vulnerabilities, including 3 critical and 16 high findings.
Users who need first-class image, audio, video, or file attachments inside notes: open issue 232 requests that capability.
Firefox-only users who rely on web clipping: the README links a Chrome extension, while open issue 208 requests a Firefox version.
Knowledge bases that must automatically retire stale claims: open issue 157 says there is no expiry field, expired-note view, or chat filter for outdated atoms.
People seeking a plain Markdown editor without an AI service: embeddings, tagging, wiki generation, and chat require Ollama, OpenRouter, or another compatible provider.

Setup reality

Our sandbox installed 928 npm packages in 22 seconds and used 515 MB. The build passed in 22 seconds, and the test command passed in 11 seconds. Npm audit reported 29 known vulnerabilities: 3 critical, 16 high, 8 moderate, and 2 low.

Desktop releases include the server, while Docker Compose starts an API server, web frontend, and nginx proxy. Self-hosting requires an ATOMIC_SETUP_TOKEN, persistent SQLite data, and an AI provider for embeddings and generation. Ollama can keep that work local; hosted providers require API credentials.

Developing the whole project needs Node 22+, Rust, and platform dependencies for Tauri 2. Remote MCP uses bearer tokens and a public HTTPS endpoint. Changing embedding models can affect the vector space, so provider and model choices deserve the same care as database backups.

Atomic turns notes into a searchable graph and generated reference

Atomic stores Markdown notes as atoms, then chunks and embeds them for semantic search. Similarity drives links and a spatial canvas, while language models can extract hierarchical tags, synthesize cited wiki articles, answer questions, and produce scheduled reports from the stored material. The source note remains the unit a user reads and edits, which is easier to audit than a knowledge product that hides everything inside a chat transcript.

The application reaches beyond the desktop. A Chromium extension captures pages, an iOS client reads and writes atoms, RSS feeds can create new entries, and multiple databases share one registry. The repository's primary GitHub language is Rust, with a React frontend and Tauri 2 desktop shell. That breadth makes Atomic a full application rather than a reusable note-processing library.

What happened when we ran it

Our sandbox installed 928 npm packages in 22 seconds and consumed 515 MB on disk. The build completed in another 22 seconds, and the supplied test command passed in 11 seconds. At commit 825e223, the checkout held 997 files, about 239,666 lines of source, and 19.8 MB before the installed dependency tree.

The audit result changes the recommendation. Npm reported 29 known vulnerabilities: 3 critical, 16 high, 8 moderate, and 2 low. Our measurement does not say which application paths are reachable or whether a compensating control exists, so it would be wrong to turn the count into 29 exploitable Atomic bugs. It does establish that the installed tree needs investigation before an internet-facing deployment.

Our scan also found 5 CI workflow files, a Dockerfile, and Compose configuration, with no directory literally named tests. The passing 11-second test command shows that test coverage exists somewhere in the project structure. These results cover repository mechanics in a fresh 3-CPU, 8 GB Debian container; they do not measure search quality, embedding accuracy, or generation quality.

Docker starts three services and still needs an AI provider

The Compose route starts the API server, web frontend, and nginx reverse proxy. An ATOMIC_SETUP_TOKEN lets the first browser claim the instance. The standalone Rust server and Fly.io instructions provide other deployment paths, while desktop releases bundle a Tauri client with the server sidecar. Persistent storage and backups remain the operator's job in a self-hosted setup.

Atomic cannot generate its semantic layer from SQLite alone. OpenRouter, Ollama, or another OpenAI-compatible endpoint supplies embeddings and language-model calls for tagging, wikis, reports, and chat. Ollama is the privacy-oriented choice when suitable models fit locally. A hosted API means notes or derived prompt material leave the machine under that provider's policy, even though the Atomic database stays under your control.

MCP grants both reading and writing access to the knowledge base

The embedded MCP server exposes semantic search, similar-note lookup, tag and database browsing, wiki and report retrieval, plus tools to create, ingest, update, and edit atoms. Desktop mode uses a bundled stdio-to-HTTP bridge that reads the local token. A remote client connects to /mcp with a bearer token created in settings or by the server CLI.

That is useful for Claude Code or another agent that needs durable project research, but the token is powerful. It can change the same knowledge base used for later retrieval. Give each remote client its own revocable token, keep the 515 MB application stack behind HTTPS, and avoid placing the endpoint on the public internet before reviewing the 3 critical and 16 high audit findings.

Generated wikis depend on source quality and provider behavior

Wiki synthesis includes inline citations back to atoms, which gives readers a path to inspect supporting notes. Release v1.45.0 fixed structured generation that could silently return empty tags or wiki updates with some providers. It also changed gateway-padded success responses into retryable failures and improved schema instructions for smaller local models. These fixes show why provider compatibility deserves its own acceptance set.

Staleness is another limit. Open issue 157 describes notes about fast-changing subjects remaining available to chat after their useful date because Atomic has no valid_until field, expired-note view, or filter. Citations prove where an answer came from, not that the source is current. Anyone storing operational or health research should add dated tags and review routines until the product can enforce expiry.

The capture system still has platform and media gaps

The browser extension queues captures offline and syncs them when the server returns. The README links the Chrome Web Store, while issue 208 asks for Firefox support. Users committed to Firefox or a Firefox-derived browser will need another import route. RSS ingestion and direct URL ingestion cover some of that gap, though they are not a replacement for clipping an authenticated page.

Atoms are Markdown-first. Issue 232 requests first-class uploaded images, audio, video, and general attachments, which means that media-library use is outside the documented feature set today. Atomic can store source URLs and captured web content, but buyers migrating a notebook full of scans, recordings, and PDFs should test the importer against a representative folder before choosing it as the permanent home.

August 2026 releases show active work on AI failure modes

GitHub recorded 1,927 stars and 31 combined open issues and pull requests when fetched. The last push was August 9, 2026, followed minutes later by v1.45.0. Issue activity continued through August 18. The release cadence and detailed failure fixes indicate active maintenance, while the issue list still contains product gaps around media, expiry, and browser support.

Atomic is a persuasive package for one person's research archive because notes, search, synthesis, capture, mobile access, and MCP all share the same data. Our 55-second successful run lowers the cost of evaluating it. The 29 dependency advisories raise the cost of deploying it carelessly, so the sensible trial is local, backed up, and kept away from an exposed server until the audit is understood.

Alternatives

ProjectWhat it isPick it when
SiYuan gh↗A local-first knowledge system with block references, databases, and self-hosting.pick this instead when structured notes and a mature editor matter more than AI-generated wikis and MCP access.
AppFlowy gh↗A self-hostable workspace for documents, databases, and team collaboration.pick this instead when collaborative workspace features matter more than a personal semantic graph.
Logseq gh↗An outliner and linked-note application centered on local files and graph navigation.pick this instead when daily notes and manual links matter more than generated tags, reports, and articles.

What people are saying

  1. [github-trending] kenforthewin/atomic
  2. [hackernews] Atomic Clocks
  3. [hackernews] Discovery of a multicomponent alloy forged by the Hiroshima atomic blast

Sources

  1. Atomic README
  2. Atomic repository facts
  3. Atomic v1.45.0
  4. Media upload request
  5. Knowledge expiry request
  6. Firefox extension request

More self-hosted reviews

sparkDash · workbuddy2api-panel · jeff · OpenGFW · splash · quivr · the whole board →