How do you teach undergraduates to think like social engineers without crossing ethical or legal boundaries? This talk presents the design and infrastructure behind a new classroom project where students explore human-centered vulnerabilities through staged environments. By simulating the reconnaissance phase of the OWASP Web Security Testing Guide (WSTG), the project demonstrates how the human element is often the key to initiating technical exploits. Using only a WordPress-based mock company, carefully crafted fake documents, and in-person props, students are guided through safe, low-tech exercises such as dumpster diving and baiting. These activities help them understand how attackers piece together discarded fragments of information into powerful pretexts, often as the initial vector for attacks found in the OWASP Top 10.