Fullstory Intelligence Report
Muse is here. Can you see what
it’s doing on your site? Fullstory can.
Autonomous computer-use agents can search, compare, and fill a cart without ever saying they’re agents. They won’t tell you. But their behavior will.
Fullstory’s unique approach to data capture picks up every move, click, and pause. The agents may be quiet, but Fullstory’s data isn’t.
Can behavior alone give an agent away?
Muse is a computer-use agent. That’s a fancy way of saying it drives a web browser like you do. It reads the page, moves the pointer, clicks, and types. What it doesn’t do is introduce itself. No name tag. No “Hi, I’m a bot.” It just shows up and gets to work.
As a proud Fullstory data scientist, I figured identifying Muse sessions would be easy. We already have signals that flag suspicious activity and automations. Build a segment, watch a few sessions, maybe get our new MCP tools involved, and be done by lunch.
I was, in fact, not done by lunch. Building segments and watching sessions was just the start. I even started to wonder if spotting an agent like Muse from behavior alone was possible. No self-report, no bot label, no help. But the more I dug, the more promising it looked.
To get started, I gave Muse a real errand on an internal mock shopping site we use for testing. The kind of errand any busy parent would love to hand off:
The prompt“My son has a football game on friday and i need to bring bananas and oranges for halftime. There are 20 kids on his team. Go to <mock site> and buy some bananas and oranges for me. They need to arrive before friday at 10:00am”
Once the session showed up in Fullstory, I watched Muse shop for me. It searched, compared products, and filled a cart. It didn’t even complain about the price of fruit for 20 kids. I did.
Then, I went to the same site and ran the same errand myself, like a good parent. Fullstory captured both sessions. Once I started digging through all the clicks and scrolls, the two looked a lot more alike than I expected.
In this post, I’ll show what finally told them apart. I’ll also show why Fullstory is in a rare spot to catch this new wave of computer-use agents. We capture every click, scroll, and pause, not just the events someone thought to tag.
Starting with the signals Fullstory already has
The obvious place to start was with the tools we already have. Fullstory ships 25 behavioral signals for spotting suspicious activity. They fall into four groups: how a visitor acts, what it calls itself, where it connects from, and what it types or takes. After a few more test runs, I noticed that two of these signals fired consistently across suspect sessions. These signals are shown in blue, and neither one said anything explicit about being an agent.
How it acts · 9
What it calls itself · 5
Where it dials in from · 2
What it types or takes · 9
Both of the signals that fired told the same story: the mouse didn’t move as expected human behavior would indicate. True, but not exactly a smoking gun. For example, one of the signals fired on 7 of the 8 pages Muse visited in its session. Seems helpful. Until you see that it also fired on 1,017,795 other non-Muse sessions that same day. By itself, this signal can’t tell an agent from anyone else.
pages in Muse’s session where the pointer signal fired.
other non-Muse sessions that same day where it also fired.
of the human comparison sessions had at least one page where it fired.
It turns out people leave the mouse alone all the time. In fact, this small sample size of human sessions used for comparison showed 92% of real sessions had at least one page where this signal gets triggered (nobody touched the page). We read. We scroll with the keyboard. We get up for coffee. So, the “mouse didn’t move” can’t tell an agent from a person who’s just reading.
And the signals built to catch agents by name (ai_agent, ai_crawler, ai_assistant, ai_vendor)? Silent. Muse doesn’t wear a name tag, remember?
Does that mean our signals are wrong? No, they answer a different question. They’re built to say “look here” on a single page, not to judge a whole visit. When we add them up across every page things start to get interesting.
Comparing Muse with a person
I went fishing. I pulled sessions that were clearly human. I pulled sessions that acted a lot like Muse. I lined them up and started comparing. Two things started to rise to the top: how the mouse moves and how long people pause.
When you move a mouse, your hand curves a little on the way. But agents don’t have hands (yet; kidding, kind of). They go straight, or they don’t move at all. Take one Muse visit shown in the table below. Across eight pages, it moved the mouse just twelve times. Not one of those mouse movements had an attached curve. The other Muse-like sessions looked almost the same. Those of us with hands (read humans)? Typically hundreds of moves on a single page, all with an attached curve.
Agents and humans also think at different speeds. People pause just long enough to process what they see, then act. These pauses tend to last between a tenth of a second and two seconds. I call this the think window: about how long it takes to read a label or pick a button.
As of today, agents don’t think like this. They either act right away or sit idle for minutes at a time. Pedal to the floor, or parked. No in between.
So I measured the mid-band: the share of pauses that land in the human-like think window. For people, it was about 60%. That’s 6 out of every 10 pauses are spent reading, deciding, or just processing. For agents, about half that.
| # | Page | Moves | Curves | Clicks | Mid-band |
|---|---|---|---|---|---|
| 1 | search | 1 | 0 | 0 | 0.500 |
| 2 | product | 1 | 0 | 1 | 0.286 |
| 3 | product | 1 | 0 | 1 | 0.429 |
| 4 | product | 1 | 0 | 1 | 0.429 |
| 5 | cart | 0 | 0 | 0 | 0.500 |
| 6 | product | 1 | 0 | 1 | 0.375 |
| 7 | product | 1 | 0 | 1 | 0.375 |
| 8 | cart | 6 | 0 | 6 | 0.208 |
Curves are moves that bent on the way, because hands curve and bots tend to go straight. Mid-band is the share of waits lasting 100 ms to 2 s, roughly the pace of thinking. It is noisy on short pages, and the full session reads 0.329, which is inside the range I later saw for bots.
Numbers are nice, but I like to see things. I picked one Muse visit and one human visit. Then, I redrew both from the raw mouse data Fullstory captured: every click, every move, every pause. Earlier pages fade out as each visitor moves on. Hit play to watch.
A Muse agent
A verified person
Watch what happens between clicks. Muse’s pointer just sits there, then it pops up right where it needs to be. It never travels. It only teleports. The human pointer has continuous movement. It drifts while reading and wanders while deciding. Sure, this pair is extreme, but the pattern holds. I saw the same split across many sessions I compared. People are there the whole time. Agents show up in flashes with bursty activity; click, vanish, click.
A difference in shape, not in any one action
No single action gives an agent away. Look at any one page, and a flag or two might fire. What happened? Unsure. It’s a smoke alarm that won’t tell you which room is on fire.
Zoom out, and it’s a whole different story. Roll all 25 signals up across every page of a visit, and a shape starts to form. A person is there the whole time. We read, drift, and second-guess. An agent shows up, does the job, and leaves. No dawdling, no second thought, no worries about the price of citrus. One page is a data point. A whole visit is a personality.
I tested this idea across a batch of sessions. For each one, I measured two things: curves per page, and the share of pauses in the mid-band. Then I plotted them: curves per page on the y-axis and mid-band pauses on the x-axis. The results were telling: two tidy clusters and not much between them. The agents huddle in the bottom left; the people sit up and to the right. My Muse session? Right in the middle of the agent cluster. Hook, line, and sinker. Hover a point to see the session.
What this doesn’t show yet
Let me be clear: this was a tiny experiment. A weekend fishing trip, not a finished product. I only used about 25 sessions. I watched and labeled each one by hand. I haven’t tested it robustly on real customer traffic.
Still, this shows what is possible. And it only works because Fullstory captures every move, click, and pause. Without that, I’d be guessing. Fishing with no bait.
So the real question is: do these patterns hold up on your traffic? There’s one way to find out.
What you can explore today
Want to try this yourself? You can start looking using Fullstory today. This segment uses the No Pointer Curve signal. It’s already in the app, and it’s built into our MCP server, so your AI assistant can find it too.
Event filters · users who performed these events in the same session
I’ll keep posting as we sharpen these signals and learn more about how autonomous computer-use agents behave. Up next, a tricky handoff: what happens when a human and an agent trade off the same session.

Written by Logan Thomas
Sr. Data Scientist II at Fullstory