I found an RFC that ... uh, didn't dispute that. (It doesn't actually say "do not HTML escape" -- but reading it in context and it's clear that HTML escaping is not wanted there.)

Wade.